package web4;

import javax.servlet.*;
import javax.servlet.http.*;
import java.io.IOException;

public class LoginServlet extends HttpServlet {
    protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
        String username = request.getParameter("username");
        String password = request.getParameter("password");
        String captcha = request.getParameter("captcha");
        HttpSession session = request.getSession();
        String sessionCaptcha = (String) session.getAttribute("captcha");

        if (captcha.equals(sessionCaptcha) && "admin".equals(username) && "password".equals(password)) {
            // 登录成功，跳转到首页
            User user = new User();
            user.setUsername(username);
            user.setPassword(password);
            session.setAttribute("user", user);
            response.sendRedirect("index.jsp");
        } else {
            // 登录失败，友好提示
            request.setAttribute("error", "用户名或密码错误，登录失败");
            request.getRequestDispatcher("/login.html").forward(request, response);
        }
    }
}
